- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
I am running R81.10 with GA JHA take 130 installed on my gateways and SMS.
I have a External Custom Intelligence Feed named Talos_blacklist configured on my gateway cluster via the CLI.
I have a IP that is on that blacklist that gets by design of the feature.
However I need to make an exception for this IP address and everything I have tried in SmartConsole does not work, traffic to the IP in question is still dropped due to my Talos_blacklist.
In the example with my screen shots the source is 10.1.1.10 > 185.242.113.224 (black listed IP). From the log card I have selected add an exception, select the defaults, the exception is created (see screen shot), I install threat prevention policy and traffic is still blocked from my source to the destination due to the Talos_blacklist.
I have also tried creating my own threat prevention rule and assigning the source and/or destination to a dummy no threat prevention policy that doesn't have any TP enabled and that does not work as well.
Is it possible to make exceptions for IP's on External Custom Intelligence Feed's and if so how can I create one that will work?
Thank you in advance.
Hey,
We will check it and provide an update. Thanks!
Hey,
We just released this functionality in R81.20 JHF Take 43.
If you need this on top of R81/R81.10 JHF, you will be able to use this feature in the upcoming jumbo release.
Unfortunately the IP exclusion feature is not supported via the SmartConsole for now.
In order to add IP exclusions, please locate a file containing a list of IP addresses with an end-of-line delimiter at $FWDIR/conf/ip_whitelist.eng.
IP addresses in the ip_whitelist.eng file will be exempt from enforcement actions, regardless of their presence in any of the threat intelligence feeds.
Hi,
Thank you for the information.
For an exclusion in R81.10 to we change the ip_whitelist.eng file on the security gateway or the SMS?
Can you please provide an example for the syntax to add a IP as a end-of-line delimiter?
Hey.
The file should be located on the security gateway.
Example of ip_whitelist.eng:
192.0.2.146
192.0.2.147
192.0.2.148
Hi @TPExpert ,
I opened ip_whitelist.eng in vi editor, added a IP on my custom intelligence feed, write quite, installed tp policy, and traffic to that IP is still prevented.
As I wrote in my first comment, it wasn't released yet in R81 and R81.10. I guess that it will be integrated in the next jumbo release.
Sorry I misunderstood. Thank you for the clarification. I will wait for the next hotfix for 81.10.
@TPExpert : It would be nice if this would be documented in R81.20 Threat Prevention Administration Guide and sk132193.
I was told by TAC (DEBUG), that the new architecture for custom IOC feeds, which was introduced in R81.20, is much more robust and supports at least 2 million patterns/observables is only used when importing custom IOC feeds through SmartConsole, not using the old way over CLI.
So this raises the question, if this new ip_whitelist.eng file is working for both SmartConsole and CLI feeds, or only SmartConsole.
Hello Tobias,
Correct, the new functionality is applied for both types of feeds; locally managed CLI.
We will update the SK with the relevant information.
Thanks!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
12 | |
9 | |
7 | |
7 | |
6 | |
6 | |
5 | |
5 | |
5 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY